Is there more on this mitm cert spoofing somewhere I can read up on? Sounds intriguing to say the least
Also LE actually knows this attack is possible and mitigates it by validating the challenge from multiple sources so the attacker would need to be in the middle of all the LE validators and your servers.
https://portswigger.net/daily-swig/lets-encrypt-deploys-new-...
You might have access through editing a proxy rewrite rule, for example.
In the attack above you use your own SSL provider for a cert (LE not involved) and you overwrite the cert in a sense that existed before. You choose a provider that just validates with a file location. It's an attack which already requires compromise.
It’s not hard to monitor cert transparency logs, which will show this new cert.